Enforcement
EN PVV Overijssel: Insufficient fulfilment of data breach notification obligations
€7,500 fine - Dutch Supervisory Authority for Data Protection (AP)
Content
The Dutch DPA (AP) fined the Overijssel local branch of the PVV party EUR 7,500 for failing to notify the AP of a personal data breach, in violation of Art. 33 GDPR. An email regarding the convening of a meeting had been sent via an open distribution list due to a human error. Since the total of 101 recipients were addressed as 'Friends of the PVV' in the email, the political beliefs of the data subjects were thus disclosed to all addressees.
GDPR Articles: Art. 33 GDPR
Industry: Public Sector and Education